CryptoInc logoCryptoInc
HomeAll NewsBitcoinEthereumDeFiAltcoins
HomeAll NewsBitcoinEthereumDeFiAltcoins
CryptoInc logoCryptoInc

AI-curated crypto news from top sources, delivered fast.

Categories

  • Bitcoin
  • Ethereum
  • DeFi
  • Altcoins

Resources

  • All Articles
  • Search
  • Sitemap
  • RSS Feed

Legal

  • Privacy Policy
  • Terms of Use
  • Disclaimer

© 2026 CryptoInc

Not financial advice.

LayerZero Post Mortem Shows Lazarus
BackEthereum

LayerZero Post Mortem Shows Lazarus

Apr 20, 2026(about 6 hours ago)2 min read2 viewsSource: The Defiant
$ETH

LayerZero Post Mortem Shows Lazarus Group's $290M Heist

A recent LayerZero post mortem reveals that North Korea's Lazarus Group executed a $290M theft from KelpDAO's rsETH bridge by compromising two LayerZero RPC nodes.

Attack Vector and Methodology

The attacker hacked the nodes, deployed malware to feed false transaction data exclusively to LayerZero's verifier while maintaining honest responses to monitoring systems, then DDoS'd legitimate RPC endpoints to force the verifier to rely on the poisoned nodes.

Key Steps in the Attack

  • Compromising two LayerZero RPC nodes that feed data to the protocol's verifier
  • Deploying malware to feed false transaction data
  • DDoS'ing legitimate RPC endpoints

LayerZero's Response and Contagion Limitation

LayerZero Labs confirmed KelpDAO used a 1-of-1 DVN (Decentralized Verifier Network) setup—a single point of failure the protocol had repeatedly warned against—limiting contagion to KelpDAO's bridge with no reported impact on other assets.

Security Implications

Security researchers noted the attack vector raises unanswered questions about how the attacker obtained the RPC node list and achieved root-level access to production infrastructure, suggesting either a prior unreported LayerZero compromise, a breached deployment pipeline, or insider access rather than a Kelp-side misconfiguration.

Insights from the LayerZero Post Mortem

The LayerZero post mortem shows that the attacker stole $290M in unbacked rsETH before the malware self-destructed and deleted all traces.

Key Takeaways

  • The Lazarus Group executed a $290M theft from KelpDAO's rsETH bridge
  • The attack was made possible by compromising two LayerZero RPC nodes
  • LayerZero's 1-of-1 DVN setup limited contagion to KelpDAO's bridge
  • The attack raises concerns about the security of DeFi protocols

Frequently Asked Questions

What was the extent of the damage from the LayerZero attack?

The attack resulted in a $290M theft from KelpDAO's rsETH bridge, with no reported impact on other assets.

How did the attacker gain access to the LayerZero RPC nodes?

The attacker's method of obtaining the RPC node list and achieving root-level access to production infrastructure remains unclear, with possibilities including a prior unreported compromise, a breached deployment pipeline, or insider access.

#Cryptocurrency#defi security#Blockchain#Lazarus Group#LayerZero

Related Articles

Hold Through Everything: XRP's Strong Position
Ethereum

Hold Through Everything: XRP's Strong Position

XRP's strong position in the market is due to its access to key institutions and talent strategy. Ripple is strengthening XRP's long-term value through strategic acquisitions.

20 APR '26
$ETH$XRP$UNI
Ethereum Risk $1000: Trader Warns
Ethereum

Ethereum Risk $1000: Trader Warns

Ethereum risk $1000: Top trader Ansem warns of a looming price collapse due to DeFi exploits and capital outflow. Ethereum's bullish thesis is under fire.

20 APR '26
$ETH
Days After $292M DeFi Hack, Vitalik Buterin Defends Ethereum
Ethereum

Days After $292M DeFi Hack, Vitalik Buterin Defends Ethereum

Vitalik Buterin defends Ethereum after $292M DeFi hack, emphasizing trust and security. Ethereum's roadmap includes gas limit increases, zkEVM rollout, and post-quantum preparation.

20 APR '26
$ETH
KelpDAO Fallout Deepens: Ripple Flags Security Gaps
Ethereum

KelpDAO Fallout Deepens: Ripple Flags Security Gaps

KelpDAO's rsETH bridge exploit resulted in $293 million loss. Ripple's CTO flags security gaps, while Justin Sun calls for hacker negotiation.

20 APR '26
$ETH$LINK